Skip to content

Close local Fabric service and TPM attestation gates - #30

Merged
rblake2320 merged 1 commit into
masterfrom
feat/production-closure
Jul 20, 2026
Merged

Close local Fabric service and TPM attestation gates#30
rblake2320 merged 1 commit into
masterfrom
feat/production-closure

Conversation

@rblake2320

Copy link
Copy Markdown
Owner

Scope

  • installable/live-tested Fabric V2 Windows SCM service with direct ctypes IOCP completion handling
  • machine-scoped non-exportable TPM identity key and nonce-bound PCR quote verification
  • durable replay rejection, redacted evidence, packaging, runbooks, and bounded release claims

Verification

  • 841 passed, 11 skipped
  • hardware TPM suite: 5 passed
  • package build and wheel-content inspection: passed
  • release audit: 46 passed, 0 warnings/failures
  • exact built commit installed system-wide; SCM service Automatic/Running; live ACK in 0.969 ms

Boundaries

  • one-host mechanism evidence, not fleet deployment
  • manufacturer/EK certificate-chain trust, remote enrollment/revocation, signed installer policy, independent assessment, and ATO remain external deployment gates
  • Fabric V2 is not claimed as the default route for every SelfConnect workload

@rblake2320
rblake2320 marked this pull request as ready for review July 20, 2026 20:04
@rblake2320
rblake2320 merged commit 787a6b8 into master Jul 20, 2026
1 check passed
@rblake2320
rblake2320 deleted the feat/production-closure branch July 20, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant